Skip to content
TrackPodcasts
businessMar 12, 2026

How Medical Device Cyber Challenges Could Become Easier

About this episode

Medical device cyber challenges are among the most complex for manufacturers and healthcare delivery organizations for a variety of reasons, but there are some promising developments underway that could help ease the pain, said Phil Englert of the Health Information Sharing and Analysis Center.

Get every episode summarized

Each time Data Breach Today Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

179 searchable segments. Every word is indexed and playable.

How Medical Device Cyber Challenges Could Become Easier

Data Breach Today Podcast

0:00
0:00

Full transcript

Data Breach Today PodcastHow Medical Device Cyber Challenges Could Become Easier. Machine-transcribed; use the interactive transcript above to jump the player to any line.

I'm Mary Ann Kolbosek-McGee, Executive Editor at Information Security Media Group. I'm here at HIMS26 today, speaking with Phil Angler, who is Vice President of Medical Device Security at the Health Information Sharing and Analysis Center. Welcome Phil. Thanks Mary Ann, really happy to be here and see you. So Phil, the Health ISAC recently issued its 2026 threat report. In terms of medical device manufacturers, the report said that their top cyber challenges include integrating security into the design and development process, providing regular and secure updating and patching for medical devices, and designing for the ongoing security of medical devices over their long operational lifespan. Why do you think those issues are so challenging for medical device makers? What makes those challenges so difficult? So a couple of things, there's lots of different infrastructure technologies that support medical

devices, so connecting the interoperability, and also maintaining clinical functionality is always a challenge, right? And so we need to update devices, you know, to stay current with the interoperability challenges that we have today and the threats against that. And then also protect the clinical functionality and make sure that that's not altered. So that creates a friction, if you will, between two purposes on the devices. And so manufacturers are beginning to do a couple of things, right? They're building discipline into their CICD cycle, right, in processes, they're using consistent tools across their portfolios. And so this is building the kind of consistency that we want. As far as patching and updating, these devices have to be built to operate in a broad variety

of healthcare, network, infrastructures. And so they have a lot of capabilities, you know, that they can operate, you know, on Wi-Fi or connected over Bluetooth or connected directly, you know, over the Ethernet. And so updating them requires different levels of pieces. Anytime there's a change to that, they don't have to go back and validate that. And that can be a four, six, eight month process for more complicated devices. So now Phil, how might AI tools help to address medical device cyber issues looking forward? For instance, how might AI tools be helpful in medical device vulnerability management by hospitals and manufacturers or managing legacy devices, any thoughts on that? So yeah, there's a real opportunity, right, as manufacturers are becoming more comfortable with sharing S-bombs and their hospitals and healthcare systems know what components

are in their medical devices. When things like, when tooth come out, they can then scan their asset and sub-asset management systems, identify which devices may have this component, reach out to those manufacturers, figure out whether that's affected or impacted and whether they have to address it, right? And also understand, you know, which devices or technologies these vulnerabilities may reside in and whether that's, you know, critical to their mission so it'll help them prioritize that. So the promise of AI is really opening it will require good discipline and true transparency on a lot of this and manufacturers are moving in that direction but not all at the same pace. So, you know, the more consistent and high quality S-bombs we get, the more effective will be in managing and maintaining the resilience of our medical device infrastructure. Is AI being used right now at all for vulnerability management, do you think, or is it more of

like something that's more piloted or just kind of looked at? So I think piloted or maybe even experimental, right? Folks see the promise of it, they're working through it, you know, data quality is always a challenge, you know, around the devices and so, you know, folks are using it for the basics at this point, right? Maybe the operating systems that are out of date and whether they have that in critical infrastructure in their crown jewels and maybe want to put that on their strategic replacement plans and things like that. That's AI, they're experimenting with AI to see whether that functionality can be built in and can be leveraged. You know, the promise of AI is really the ability to manage big data, which may mean managing data outside of your, you know, beyond your own walls and institutions, right? And understanding what other folks are doing. Maybe you plan on replacing a technology and many of your peers are not, right?

And they have good reasons for doing that and that would be good to know and would be there. I expect to see some real improvements enhancements, I guess is the right thing in this area with maybe passive monitoring tools, with even with network monitoring tools or GRCs that allow us to, you know, utilize information beyond just what we know within our own institutions. And now what's most promising to you in terms of developments involving medical device cybersecurity, where are the biggest gaps that need more attention, do you think? So I think the biggest gaps is we're still iterating on what we had, you know, the clinical functionality of infusion pumps or EKGs or physiological monitors hasn't changed since they were developed back in the, you know, 70s, 80s and 90s, right? That's still there and rightfully so, they do the clinical functionality correctly, right? Trying to then build and add in the cybersecurity element is a challenge for organizations because

rightly so, this should be built from the ground up. And so I think manufacturers, I mentioned it earlier, are building discipline into that, having the right tools, making sure that the devices that are getting modified, even if incrementally are incorporating, you know, the best of the cybersecurity controls that they can put in place and that they understand what those risks and exposures are. And then I think the other thing is manufacturers are beginning to say, you know, what we cannot continue to develop on this platform, we're going to have to develop a new platform, right? And then manufacturers are then beginning to use the SDLC from the ground up, right? Like let's make it secure, then let's make it functional, right? And that's a different thing. We're beginning to see this even in, you know, emerging technologies and startups where they know that cybersecurity is important. They're reaching out to advisory groups and seeking, you know, information earlier and earlier, farther and farther left, right? Which is good, which is where we want it to be, right?

It's still the challenge, though, of these devices that we know are going to be used for 10, 15, 20 years, you know, so they have a much longer lifespan than the components that they're built on. These manufacturers have to think about, how are we going to keep these devices updated, right? And that is a challenge in that, you know, in order to have that connectivity, to do it at scale, to do it with a low, let's say, overhead cost, right, and make that manageable. And enticing means that we're going to have to have connections and build that trust. So manufacturers are going to have to then demonstrate, you know, that the risk they introduce to keep their devices, you know, secure while they're in their, in their environments, you know, are beneficial. That way the risks of having another, let's say, hole in the firewall or exposure. So in your opinion, have the, has the FDA's medical device cyber requirements for pre-market

approval helped at all in terms of pushing medical device makers to take cyber issues more seriously and intentionally into their product designs? And what else might be needed to help further that progress, do you think? So I think, yes, it absolutely has helped. The FDA guidelines are very forthcoming, they're very, they're not as prescriptive as many manufacturers would like that, but they have what I call the security, you know, authentication encryption, you know, authorization, the standard stuff that, that we protect our devices with, including patching and updating, and those are important elements. They are, as they learn, they are becoming more discretionary in what they approve, what they accept, and manufacturers are recognizing this. I think for a while there was a bit of inconsistency, and manufacturers are willing to rule the dice. I think that goes away, right? And the other thing I see is the FDA is becoming more active in the post-market monitoring

and enforcement area. And this is very encouraging because that's what's really going to drive legacy devices just being unacceptable and intolerable, you know, from a cyber security risk. And that's where the HDOs will have to make that investment, make that decision, you know, to replace it. It doesn't mean they're going to eliminate all of the risk, but they'll do it and it will become a decision factor, you know, in the strategic replacement planning. So that, I think, will change and drive things much more. The other thing is, as we see the rest of the world, whether it's EU or Singapore or Japan, you know, formalizing their standards, right? And even though they're not identical to the FDA's, there's enough similarity, you know, that manufacturers are saying this is not just an American issue, you know, it's a global issue, and that helps drive their businesses and business decisions. And in terms of emerging or new medical device technologies, we hear a lot about implantables,

brain implants, and neural sorts of things, anything that's, you know, particularly exciting to you right now, not from the society, from a cyber perspective, but in terms of the innovations that are coming out with medical devices. You know, I think the things we're doing with the human machine interfaces is just phenomenal. You know, the fact that we can control pain, we can reduce the symptoms of Parkinson's disease with, you know, electronic stimulation. You know, we can manage, we're going to be able to manage not just, you know, insulin levels within the body, but detect and remind patients about medications, one of the most challenging things, you know, for health care is the continued, the discipline behind care regimes, right, so patients often will take medicines for a while, maybe not finish them out or feel like, oh, hey, I feel pretty good, I don't need my medicine today. The ability to detect whether that medication is present and remind patients, you know,

much the way, you know, we rely on our health devices to remind us to take steps or stand up and stretch and things like that. So it's just an awareness element. That will, I think, increase, you know, the public perception for that and improve, you know, the discipline around care delivery. Do you think that will increase also the kind of the threat and the risk sort of landscape in terms of, you know, new ways of hackers kind of tampering with things or? Yes, yes. I think the possibility is there. Every time we're doing that, right, any time we have innovation, people find a way to exploit it right now, if we're going to have massive, you know, or common interfaces between the human, so now it's not just the risk will change, perhaps, we won't just have, is this the correct reading, right, we're going to have to ensure that we're applying the correct therapy, you know, and that will frighten a lot of people, but I think the

promise is worth it, I think, as we learn, you know, and we'll learn to protect on the front end, because we know of, you know, how hostile an environment we live in and how that's there so far, we've been very fortunate that threat actors, whether a nation state or organized crime or others, you know, have really just pursued the monetary benefit and haven't really, we haven't recognized the threat or the change to therapies, but that's not out of the realm of possibilities. And feel anything else that you're keeping a close eye on these days involving medical device cybersecurity that we haven't touched upon? I think the one thing that we're really, and really excited about, a couple of things we're working on within Health ISAC and within the Medical Device Security Group, right, is we brought together manufacturers, we brought together healthcare delivery organizations and we said, what are, let's say the security baselines, right, so being able to provide

a set of agreed upon, let's say consensus baseline controls that HDOs will look for in their medical devices, and then describe those to manufacturers, right, and have them. So they're delivering the kind of technologies that HDOs are looking to, you know, implement. So hopefully that will, you know, shorten the evaluation and approval cycle, it will make more consistent how we configure and hang these devices on our network, and it will make more consistent and more efficient how we protect these devices in our environment. So that's going to be, you know, a real benefit, I think, you know, the fact that we have groups from both sides, you know, working on this together and collaborating and, you know, talking about it, figuring it out, you know, and then writing about it is really exciting to watch, you know, happen, and I'm just so proud to be part of that. Well, thank you so much, Phil. I've been speaking to Phil Anglert. I'm Mary Ann Kolbusak-Miggy of Information Security Media Group. Thanks for joining us.

More episodes

More from Data Breach Today Podcast

View all episodes →